Conversation

Google supports using the hardware-based keystore in Android devices as a full U2F key including the button-based authorization, but there isn't generally a trusted display so there's only physical confirmation of a request with the OS generally trusted to display the request.
1
Setting this up is a different process from setting up the Google prompt and it's a way better choice to add the phone as a security key. It's best on devices with a high quality HSM-based keystore but even with the traditional TrustZone keystore it's way better than the prompt.
1
Show replies